← Home

IEC 62443-3-1 Clause 5.8 – Password Distribution and Management

Teaching note: Paraphrased from IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007) for learning. The technical report is informational, not a requirements standard. Confirm wording in the published TR. Later normative parts (2-1, 3-3, 4-2) state the shalls.

Reference: IEC/TR 62443-3-1:2009 (ISA-TR99.00.01-2007), Clause 5.8
Related: Clause 5 | 5.2 Password authentication | SR 1.5 Authenticator management | 2-1 Clause 11

Technology categories: Overview | Cl. 5 | Cl. 6 | Cl. 7 | Cl. 8 | Cl. 9 | Cl. 10

Clause 5 pages: Cl. 5 | 5.1 RBAC | 5.2 Password | 5.3 Challenge/response | 5.4 Token | 5.5 Smart card | 5.6 Biometric | 5.7 Location | 5.8 Password management | 5.9 Device-to-device


What it is

The lifecycle around passwords: generation, distribution, storage, rotation, recovery and revocation. Strength and process must match process criticality, not IT fashion.


Vulnerabilities addressed

Default passwords, sticky-note sharing, unmanaged resets, and stale credentials after staff or vendor changes.


Typical deployment

Password policy on directories and local hosts; sealed envelopes or vaults for break-glass; vendor procedures for controller passwords. Cognitive or one-time methods appear where the TR called for stronger practice on high-value systems.


Known issues and weaknesses

Emergency access fights unique passwords. Shared console accounts fight accountability. Rotation that is too aggressive drives workarounds. Rotation that never happens leaves defaults in place.


Use in IACS

Small, isolated, low-value systems that are not internet-connected can use simple passwords. Interconnected systems that hold valuable information or control valuable or hazardous processes need managed, stronger password security.


Recommendations